22.28 (L1) Ensure 'Oobe Enable Rtp And Sig Update' is set to 'Enabled'

Information

This policy setting configures whether Real-time Protection and Security Intelligence Updates are enabled during the Out of Box experience (OOBE).

The recommended state for this setting is: If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.

Note: As of the publication of this Benchmark, the setting configuration state in Intune is the sentence above after

The recommended state for this setting is:

and not

Enabled

as the title states. This was done to keep title length to a minimum.

Critical Windows zero-day patch updates should be applied during OOBE to help mitigate against malicious attacks.

Solution

To establish the recommended configuration via configuration profiles, set the following Settings Catalog path to If you enable this setting, real-time protection and Security Intelligence Updates are enabled during OOBE.

Defender\Oobe Enable Rtp And Sig Update

Impact:

None - this is the default behavior.

See Also

https://workbench.cisecurity.org/benchmarks/21719

Item Details

Category: SYSTEM AND INFORMATION INTEGRITY

References: 800-53|SI-3, CSCv7|8.1

Plugin: Windows

Control ID: c1155f250910e48618a800af0b6a8391b9acf017e69a389b3486be506e80129e